Why Your SOC Needs a Risk Operations Center (ROC)

View Show Notes and Transcript

With the mean time to weaponize shifting to minus seven days prior to disclosure, a 28-day Average Window of Exposure (AWE) is no longer acceptable. It’s time for defenders to fight back with machine-speed remediation.  In this episode, Ashish sits down with Rich Seiersen, Chief Risk Technology Officer at Qualys and former CISO of Twilio and LendingClub, to discuss the evolution of vulnerability management into Risk Operations. Rich explains the critical mathematical shift happening in cybersecurity: an explosion of CVEs hitting enterprise queues while adversaries leverage AI to exploit vulnerabilities faster than ever.  Organizations must evolve beyond traditional Security Operations Centers (SOCs) and build a Risk Operations Center (ROC) focused on prevention and controlling the terrain. Rich details how to achieve a 24-hour Mean Time to Remediate (MTTR) by using hyper-prioritization to filter out noise, evaluating reachable and exploitable risks, and employing autonomous remediation to drastically reduce organizational porosity.

Questions:
‍00:00 Introduction: Risk Operations and the Average Window of Exposure
‍01:50 Rich Seiersen’s Background (GE Healthcare, Twilio, LendingClub, Qualys)
‍03:20 The Volumetric Shift in Vulnerability Management
‍04:40 Mean Time to Weaponize vs. Mean Time to Remediate
‍05:50 Defining the Average Window of Exposure (AWE)
‍08:30 Why High Uncertainty and High Stakes Drive Risk Measurement
‍10:00 Setting a New Floor: The 24-Hour MTTR
‍14:50 Calculating Porosity and Instance Days of Exposure
‍18:20 Hyper-Prioritization and Autonomous Remediation Strategies
‍21:00 Controlling the Terrain: Sun Tzu and Asymmetric Warfare
‍24:00 Building a Risk Operations Center (ROC) vs. a SOC
‍29:00 The "Martini Glass" Filtering Approach for Exposures
‍33:00 Benchmarking Your Economic Risk and AWE Against Industry Peers
‍37:30 Qualys ROCON in Austin and How to Connect with Rich

Rich Seiersen: [00:00:00] In one week we had like 2,000 new CVEs. They took a $2.5 billion five-year loan out from their federal government because they didn't have the capital reserves to backstop that

Ashish Rajan: It's no longer humanly possible to keep measuring

Rich Seiersen: Those need to be fixed or remediated effectively within 24 hours or less.

Rich Seiersen: That's actually now the new floor. That's not the ceiling, that's like the floor, 'cause you're still looking at eight days of availability to the bad guys. We're just gonna see a lot more known exploitable, fully weaponized stuff where they're already fully being discharged prior to disclosure.

Ashish Rajan: How do you measure risk when it moves in the AI space?

Ashish Rajan: What does exposure management have to do with vulnerability management? I had a great conversation with Richard Seissman, who is the Chief Risk Technology Officer at Qualys, and we spoke about things like how is risk evolving as a measurement that we have done all this while, especially in an AI world where the mean time to weaponize, as Richard puts it, is less than 24 hours.

Ashish Rajan: We also spoke about if you are looking to uplift an existing security program, how should [00:01:00] you approach it? What are some of the tactical things you could be doing and thinking about as you evolve that program? All that and a lot more in this episode of the podcast. If you have been watching or listening an episode of the podcast for some time, I would really appreciate it if you take a quick second to drop the follow or subscribe button on whichever podcast platform you may be listening or watching this on.

Ashish Rajan: We are on YouTube, LinkedIn, Spotify, Apple, pretty much everywhere where you consume your podcasts. I hope you enjoy this episode and I'll talk to you soon.

Rich Seiersen: Peace.

Ashish Rajan: Hello and welcome to another episode of the podcast. I have Richard with me. Thank you for coming on the show, Richard.

Rich Seiersen: Ashish, thank you so much for having me.

Ashish Rajan: Maybe to kick it off, if you could share a bit about your professional background and I guess your cybersecurity, uh, professional background, that'll be a great place to start.

Rich Seiersen: Sure, happy to do that. I'm currently the chief risk technology officer at Qualys. H- historically though, I've been a a serial recovering CISO, so I've been CISO at GE Healthcare, Twilio, LendingClub, and I've been a chief risk officer in the insurance space, specifically in cyber insurance as well. Um, along the way, I've written a few [00:02:00] books co-authored "How to Measure Anything in Cybersecurity Risk," um, "The Metrics Manifesto: Confronting Security with Data," and I'm working on my third book called "The Risk Therapist's Handbook: Reasoning With Others About Cybersecurity Risk in the Company of AI."

Rich Seiersen: So that's me in a nutshell.

Ashish Rajan: Sounds like you've done a lot of work in risk. But I was gonna say for a sidebar quickly on that book as well, it's only your third book. I wrote one and I thought I had enough of it, but I guess it's never enough. People keep writing multiple books.

Rich Seiersen: I suppose everyone has their different motivations.

Rich Seiersen: For me, and this even goes back to my first book, every one has been a learning experience. It's a great way for me to do deep thinking and unlike all the cool kids you know, I don't, I'm not doing an AI book, meaning that I'm not having AI write it. Uh- Yeah ... I do my own research, do my own reading and synthesizing.

Rich Seiersen: Sure, yeah, I'll use AI to make sure I put semicolons in the right place, but yeah, I'm not big in that I use AI all day long for, writing algorithms and, you know, doing analytics and although I'm still [00:03:00] specifying it, but I'm, I, yeah, I'm-- It's a learning process. I really think it's a great way to learn and I think there's no better way for you to pen test your own ideas than writing a serious book.

Ashish Rajan: I love this. The reason I ask also, and glad you mentioned the AI component in there as well, because you're spending a lot of time quantifying risk, working on risk, and you've written books in this space as well. Uh, I'm, I'm curious of what's changed in the threat landscape of how risk is measured and viewed before AI and now with AI.

Rich Seiersen: Okay. That-- No, that's a great, great question, and I'll try to be operationally empirical here on this. It is a volumetric change. So volumetric is a term from fluid dynamics. Um, but if you think about the idea that ingress, you know, there's this volumetric, packet cannon of vulnerabilities pointed at us that are coming into our environment.

Rich Seiersen: And so that's already been happening over the last five years. It's been really an exponential hockey stick in the amount of CVEs and other things coming our way, and I think [00:04:00] that's motherhood and apple pie. We all know that. But the reality is, is that's going into an enterprise queue, right? So we have a queue of work to be done, and that queue has a, has a time to live, right?

Rich Seiersen: There's when you first disc- you first discover it to when it gets fixed or mitigated. Everyone gets that. But what's happening is shift left of disclosure. There's the really the, called the mean time to weaponize. So that's shifting left. We already saw pre Mythos that was already at minus seven days.

Rich Seiersen: And so you're seeing that thing, that weaponization period shifting left. And then with, with the queue, with the enterprise queue receiving that volumetric, packet cannon of vulns coming in, that's shifting right 'cause there's j- there's a lot of work. And by the way, the software providers, be it the Oracles, the Microsofts, et cetera, you know, they're having to do a lot more work now as well.

Rich Seiersen: So what you're seeing is this expansion of attack surface, both in terms of time as one dimension and then volume. So it's the instances, you, maybe you can think of that as the Y and time as the X. And [00:05:00] so that's a, a big difference that we're seeing. It's really empirical. It's a lot more work. It's coming in faster.

Rich Seiersen: And so that means that us, as defenders, have to s- figure out how we scale, right? How do we get both capital and operationally efficient and scale our operations? That's a lot of words, but that is empirically, operationally what we're seeing.

Ashish Rajan: So to your point, the volume has increased and I think the, I love the word you used.

Rich Seiersen: There's, so there's mean time to weaponize. Weaponize. That's the one. And there's mean time to re- So yeah, so you have mean time to weaponize and you have your MTTR, mean time to remediate. And by the way- Yeah ... means are great. They're quick back of the napkin statistics, but there's a lot of wiggle in those values, right?

Rich Seiersen: So the int, the... If you add those two numbers together- Yeah ... we call it the average window of exposure, and that's about 20. Pre-Mythos, that was already just over 28 days. We were the large- we had the largest exposure data lake in the world. We are the leading security patch provider in the world, right?

Rich Seiersen: Mm-hmm. Microsoft's the leading patch provider, but for security it's us. We have [00:06:00] decades of data on this, and the analysis shows that we're at about 28 days. And if you're paying attention, gosh, it was, was it July between Chromium, Oracle, and Microsoft, we had two thou- in one week we had like 2,000 new CVEs.

Rich Seiersen: It was a large, it was a bumper crop of CVEs that we hadn't seen before. Yeah, and so out of that, by the way, KEVs, I think there was two or three KEVs, which seems that's a really small, you know, that's a small number relative to the volume. But- Yeah ... kEVs are also a lagging indicator. We're typically calls, we're 45 days in a- a ahead of CISA even announcing KEVs.

Rich Seiersen: So we're just gonna see a lot more known exploitable, fully weaponized stuff where you're, where there's ar- where they're already fully being, discharged prior to disclosure. So as that expands, that's gonna create a lot of pressure on the defenders obviously to figure out, hey, how do we scale?

Rich Seiersen: 'Cause there's asymmetric warfare going on, right? Yeah. You have the artificial intelligence in sentient adversaries. You also have your businesses that are digitally and AI transforming your [00:07:00] security. You're stuck in the middle. How do you get scale in that? And that's really that's the discussion.

Rich Seiersen: That's the discussion we were having at BlackHat. I did a couple keynotes there, meeting with customers, and that's the discussion that obviously we're having on a, on a go forward as we look into the following year as well.

Ashish Rajan: Do you find that, and the reason I was intrigued by that word also is because a lot of people, especially in the risk department as well, and you've been a recovering CISO yourself, there is a I guess a, a known pattern for how people have measured risk for a long time.

Ashish Rajan: And this is- Yeah ... pre-AI. People knew the, knew the, let's just say the algorithm for what was needed to be done. With this volume increasing or in the number of vulnerabilities coming in, the time it takes to exploit, the time to remediate needs to be shorter, and the true positive and true negative, as you were saying Obviously the volume has increased and it doesn't s- sounds like a lot has changed and it's no longer humanly possible to keep measuring.

Ashish Rajan: So do-- what else is breaking in this new world that we're [00:08:00] moving towards? And, and if you were a CISO who's working on a security program, maybe even if you're a risk person looking at this as a program, what are you recommending to people? Like, what are you recommending to the customers for how do they look at risk for a target which seems to be moving into what you said adversaries have access to pretty smart models too, the same way we have access to models without the red light, red tapes, I guess.

Rich Seiersen: Yeah. Two things I wanna address. I wanna answer your operational question, what are we recommending, right?

Ashish Rajan: Yeah.

Rich Seiersen: So I'm gonna answer that, but before I answer that, I want to just index on one thing you said, and you may have just said it in passing, by the way. It's okay. You said it's not possible for the humans to measure any longer.

Rich Seiersen: I think you were just saying that, but I'll say this, and this is maybe just more to the general audience. AI is creating a lot of uncertainty. Listen, we're all uncertain about, A, how does it work, but what does the future mean for our careers? What does it mean from a security perspective?

Rich Seiersen: You know, are the robots gonna come and eat our faces? We don't know, right? Yeah, yeah. And so, there's a lot of uncertainty. It's when we have a lot of uncertainty [00:09:00] And what happens matters. So a lot of uncertainty and the stakes are high. When those two things happen together, that's actually when we measure.

Rich Seiersen: If you go back to science, going back even over several hundred years, that's typically the case where, gosh, it's highly uncertain 'cause the da- the data's either sparse or it's messy or it hasn't even shown up yet. Yeah. Right? And we have-- we stand a lot to use. That's actually when we do measurement. So I just wanna...

Rich Seiersen: This is not that you were saying anything wrong- Yeah, yeah, yeah. No ... but I want the audience to, audience to know that. Yeah. I think you and I are

Ashish Rajan: on the same page. You and I are on the same page- Yeah ... on that one. Yeah. 100% agree with you.

Rich Seiersen: Yeah. So there's just that I wanna say that's really, really important.

Rich Seiersen: So then, then this leads naturally into then what do we do, right? Yeah. What do we do because of the, the dynamics that you just expressed? So I, I'm gonna speak for myself, and I actually think my, uh, I think Quas would agree with this. If you ask-- Let's say you're a Fortune 100 or a Global 2- Global 2000, whatever you are.

Rich Seiersen: Yeah. And you said to me, "Rich, what do we, what do I need to do?" I, I would say assuming [00:10:00] that your ability to meet your obligations to your stakeholders, meaning you need to stay available to serve right? And you need to be able to continue to work with your third parties, and you need to continue to ensure that your employees have work to do, that you need to stay viable.

Rich Seiersen: I would argue that you want to get as close as possible to a, what do we call it, 24-hour or less mean time to remediate. So we're going back to measurement, 'cause you, we talked about measurement just now.

Ashish Rajan: Yep.

Rich Seiersen: You say, "Well, Rich, that sounds arbitrary." I'd say, well, it's not necessarily arbitrary, 'cause there's disclosure day, which is day zero.

Rich Seiersen: And let's just presuppose before disclosure, you're highly uncertain. You don't know, right? It's what-- Disclosure is now I know. There is an exposure. It's... And we're gonna, we're gonna focus on the weaponized. It's fully weaponized. Okay, now then the question then becomes, is it reachable? Is it exploitable?

Rich Seiersen: Is it real, right? So we're, this, we call this hyper prioritization, right? Is it is it externally facing? Or is it one or two Kevin Bacons away from a crown jewel? Or is it a crown [00:11:00] jewel? Mm. We, you know, is there attack paths, whatnot? So hyper prioritization. For those things that are reachable where you could actually exploit it, you could put a payload on it, you-- we do that, part of what we do call, we call it True Confirm.

Rich Seiersen: Remember I warned you true is in front of everything. Yeah. Threat Research Unit Confirm. It's reinforcement learning with AI, a lot of research involved. But anyways, so if something's actually reachable, exploitable, same segmen- same segment, across segment, external to internal whatnot, those things in your environment, your Global 2000, we would argue those need to be fixed or mediated, remediated effectively within 24 hours or less We'd say that that's like, that's actually now the new floor.

Rich Seiersen: That's not the ceiling, that's like the floor. You got... It should be less than that, honestly. Now, again, we say me- mean time to remediate. That mean time's a central tendency, so you can think about a distribution, your bell-shaped thing, where that 24 hours is, is in the center of that bell, and you have tails going on either side.

Rich Seiersen: You wanna get some of that within an hour or less like almost as close to humanly as po- we call it machine [00:12:00] speed.

Ashish Rajan: Yeah.

Rich Seiersen: You know, machine speed. And then you're gonna have a tail that's gonna go this way as well. You might have thing, maybe you're a critical infrastructure, maybe you're power and water, whatever you are.

Rich Seiersen: Maybe it's real-time trading, you're in financial services. Whatever it might be- Yeah ... you might have systems where because that, that fix requires turning something off, maybe you don't have appropriate redundancy. You can't, you know... you know, you're gonna have things that are gonna linger on the tail.

Rich Seiersen: You know, that, by the way, there's a whole ar- architectural opportunity for you there to change something. But we wanna get everything within, within that 24 hour. What that means currently in terms of the average window of exposure, though, again, given our research, is you're still looking at eight days of availability to the bad guys.

Rich Seiersen: So to the extent possible, we wanna get as close as possible to disclosure, to mach- machine you know, the machine time. Then there's this whole idea of, what we call shift left, where you may not know about explicit vulnerabilities, but where we're trying to effectively put friction in place where [00:13:00] techniques might be available to AI.

Rich Seiersen: That's a whole other discussion. But what we're saying now, what I'd, any enterprise I negotiate, Rich, what, you said 28 days is AWE. I said, "Well, that's pre-Mythos." If you were to get to you know, 72 hours or three days, by the way, that's three days MTR, MTTR, that's, that's what? 11 days of AWE. We wanna get you to that 24-hour period.

Rich Seiersen: So that's a lot of d- lot of talk, but that honestly, between first party risk, that's, you know, your cloud-native instances, all the way to your solid state stuff with IPs or whatnot, we want to get for those things that are known exploitable within 24 hours

Ashish Rajan: Which is, 'cause to your point, it's a bit scary as well to think about how short time window is, and you've been a CISO before, 'cause just to change the process to make it faster, it almost requires a lot of work on the process side of things, on the, "Hey, I need to onboard Richard," to, on the idea that we need to remediate certain things in 24 hours.

Ashish Rajan: And between all of that, you obviously find out that the frontier models actually [00:14:00] have agents breaking loose and the whole sandboxing as well. So-

Rich Seiersen: Yeah ...

Ashish Rajan: how, what's the recommendation here in terms of, say, for people who would have gone to BlackHat and gone, "Hey- Yeah ... you know what? I'm gonna uplift my security program for this AI, um, ecosystem that's growing around me, that I'm being asked to put across everywhere."

Ashish Rajan: What's your recommendation there as a s- as a, as you say, just step one, two, three, if you have in mind- Yeah ... for p- for what you recommend, especially from a risk perspective as well, and to what you said- Yeah ... where does it, Where is the right approaches to s- uh, or areas to impact or to start working on to sh- see some impact, which is a measurable risk that I can go back- Yeah

Ashish Rajan: to the business and say, "Hey this is how we are measuring it. This is why I feel comfortable."

Rich Seiersen: Yeah. So let's just assume that your, your AWE is 40 days.

Ashish Rajan: Yeah.

Rich Seiersen: You might say, "Wow, Rich, that's really bad." Well, guess what? We see that, particularly with non-Qualys [00:15:00] customers, but we see that and much worse.

Rich Seiersen: Then there are some companies that are in the cloud-native space who are at that three-day period as well. But, 28, 28.2, by the way, is the current average, and it's, it's not good enough. Let's say you're... I'm gonna use 40 just 'cause it's a nice round number. So let's say over the last two quarters, three quarters, looking at data, the amount of, uh- Of Kev class, I'll call it k- you know, known exploitable, meaning where you have commodity exploitation happening at that minus seven period.

Rich Seiersen: Yeah. Uh, let's say you had 1,000 instances of that over the last two quarters. They've-- That has arrived. That's, Kev plus asset, 1,000 instances. So if you multiply that 1,000 plus the, the 40, you're at what we'd call, uh, 40,000. We would call it 40,000 in-- 40,000 instance days of exposure. We really call that porosity.

Rich Seiersen: So you, you have that. You're... Now, if you're a successful business, by the way, successful businesses are in the business of exposing more value to more people through more channels [00:16:00] at higher velocities, right? Mm-hmm. That's what your business, your CTO's engaged in that you're investing to use AI, digital transformation to go forward.

Rich Seiersen: So the expectation is while you're at 40,000 today, that number is going to increase, and it will have a h- it's not a linear, it'll be a hockey stick increase, right? So what you wanna-- couple things that you wanna do with that number is A, you want to reduce the instances. Well, what do I mean by that?

Rich Seiersen: Unless you're able to validate same segment across segment that these things are actually, in your context, in your environment, exploitable. 'Cause you've invested, as a CISO, you've invested in inline host-based mitigations. You've made significant investments in that, right? And by the way, this includes identity.

Rich Seiersen: If you look at MITRE ATT&CK, well, roughly, give or take 30% of exploitability has some attribution in the kill chain to vulns. A lot of it is identity. A lot of the-- So, you know, what are, you know, sentient, artificially intelligent adversaries, what are they doing? They're cooking at the hibachi of techniques, right?

Rich Seiersen: And they're, they're exercising [00:17:00] those techniques against exposure. And techniques have objectives. They have movement objectives, they have, persistence objectives, they have egr- egress/ingress objectives. And so they're using tho- they're using techniques against exposures to achieve state-based objectives as they move around a porous environment.

Rich Seiersen: So that porosity, the math of that porosity is that 40,000 number. By the way, that was just for vulns. We have identity porosity, and we have semantic pros- porosity associated with AI. So each of these things, each of these exposures, vuln, identity, I say in that I'm talking about full stack, IT, OT, cloud native, et cetera, ephemeral i- identity, not just identity access management.

Rich Seiersen: I'm talking about however you wanna frame it, you know, zero trust, et cetera. PAM, MFA, all, all that jazz, right? And then you have, again, what I call semantic risk, if you look at MITRE Atlas, for example. So if you look at all those three classes, all those things that show up have mortality, meaning exposure has mortality.

Rich Seiersen: Again, bad guys are exercising techniques, right? They're cooking at the hibachi of techniques, MITRE techniques, [00:18:00] whatnot. They're using that to pivot and move around the porous environment by exercising them on exposures. You want to reduce the instance of exposures and the time on two dimensions. So how do you reduce instances?

Rich Seiersen: We call that hyper-prioritization, but that's where you're looking at, is this actually exploitable? Can I d- can I actually do that? Same segment Across segment, external to internal. And can I do that relative to the, we'll call it for lack of better, attack paths that are associated with treasure or value?

Rich Seiersen: This gets into risk, right?

Rich Seiersen: I get the idea that the environment's completely porous, and you could say, you know, "It just takes one bad apple." But listen, we have to hyper prioritize where we know there could be lost business disruption, where there could be regulatory data breach, where there could be wire fraud, where there could be extortion, where there could be espionage, and other things like that.

Rich Seiersen: We need to be able to look at that and understand, okay, how do I prioritize across this so I can reduce those instances that actually deterministically matter? Not that I'm [00:19:00] gonna stop doing rolling patches. You do, do all that general hygiene, right? Yeah.

Ashish Rajan: Yeah.

Rich Seiersen: But where I can do targeted, that reduces the instance, and then you use autonomous remediation, right?

Rich Seiersen: It could be auto PR in the first party software, where we're getting to auto PR based on policy, it goes and executes. Or from the, you're going more into the infrastructure, infrastructure as code, uh, and/or your IP-based assets where you're doing patching or mitigation. But again, this is where AI is getting involved.

Rich Seiersen: Not only have you prioritized, but you can score and say, "Hey, is there any evidence of this software and this combination where there's been rollback? Is there any indication where there could be degradation of service?" All right. Where you have a high fidelity score from AI, push that patch, right? Let's just do that now, right?

Rich Seiersen: I don't even have to scan. Boom, we go for it. And/or where we say, "Okay, this is a high availability asset. There might be some evidence of some potential degradation," we, 'cause large data lake and the universe, right? Where we'll put this on a wave-based rollout, right? Where we can just track and track so that we can reduce any sort of business disruption.

Rich Seiersen: So that's how you start getting economies to scale, and that's how [00:20:00] you start taking from an a-asymmetric warfare, you start fighting back. I'm gonna reduce the noise through, through hyper prioritization, and then I'm gonna shrink the time to live. And that's where you get to that 40,000 actually becoming, maybe that becomes 400 all of a sudden.

Rich Seiersen: And we've reduced the time to live, so you're shrinking attack surface, so you're fighting back. So operationally specifically, that's how we start operationally getting into risk management. We can talk about, if you want to, we can start talking about the monetization, return on control, all that jazz, but that is actually what... I know that's a lot. I just had a very strong cup of coffee, but I'm actually always like this.

Ashish Rajan: But I also say some of those things you called out are relevant for people who are not Qualys customers as well, like the hyper prioritization- Absolutely

Ashish Rajan: that you mentioned. Uh, it still sounds relevant even if I was not a Qualys customer, it still sounds relevant. Uh, even

Ashish Rajan: the fact that the detection, the meantime to weaponize the meantime to remediate. All of that is still relevant for most people thinking about how they approach security programs, at least in this AI world [00:21:00] as we see it. ,

Rich Seiersen: I just wanna make one comment. You, you're right, it's relevant. It's been relevant for a couple of thousand years, two, 3,000 years. If, I don't know if you've seen the movie "300," I talk about this in my keynotes. Oh, yeah. But there's a standard military strategy, even Sun Tzu talks about this, but the idea is controlling the terrain, particularly when you're in asymmetric warfare.

Rich Seiersen: How do I control the terrain and shrink what the actual adversary can do? So the movie "300," you know, they had, he had the hot gates. They didn't talk about this in the, in the movie, by the way. They did that both on land and at sea. And the reality is, the strategy was they were breaking the will of Persia.

Rich Seiersen: They were trying to prove to Persia that you, even if you suc- they did succeed, succeed in sacking Athens. Yeah. Even if you succeed, you're not gonna be able to sustain. So you could get there, but because of what happened on both the land and then in water, it's gonna be evident that the economics of this is not winnable.

Rich Seiersen: So there's this whole strategy involved. That sort of strategy is used over and over again. It's even used in modern warfare. We're just doing the same thing here. We're saying, "Okay, how can we control [00:22:00] the terrain, this hack surface, in such a way where we can actually start giving," I don't want to call it advantage, but scale.

Rich Seiersen: That's engineering s- engineering scale back to the defenders, right? And that's through hyper prioritization, again- Yeah ... and autonomous remediation. So I'll let you ask your question. I just wanted to make sure that I got that out.

Ashish Rajan: No, I, I'm, I'm glad you called that out. I mean, I guess , art of war is definitely something a lot of people still refer to, so good reference there.

Ashish Rajan: I was gonna say, in terms of people m- moving towards AI readiness gap assessments and how they should respond to it, we spoke about the impact of, hey, how do you approach an existing security program, especially if you're trying to uplift it. You had all those examples, too.

Rich Seiersen: Yeah.

Ashish Rajan: Do you find that is the new wave of how vulnerability management would be used across is-- It's almost because what you were referring to sound almost like you kind of maybe touched on this as well, but it's almost like an AISP detection is kind of where you referred to almost, where it's no longer my vulnerability [00:23:00] management process, as I remember when I was still a CISO, was the whole fact that I had a team which would work through the entire organization for the, depending on the severity of the patch and however that went.

Ashish Rajan: CVs are coming in, threat intel is coming in, but I'm primarily focused on do I have my high critical being looked after at the, whatever the meantime to remediate is. And- Right ... but now that the clock has kind of shrunk quite a bit in terms of how quickly I need to remediate Do you see the role of vulnerability management in, as a, as a-- Because you g- obviously, because you guys are like one of the, to what you said in the beginning, getting to see a lot of it more, sometimes more than what other people may on average see.

Ashish Rajan: How do you see the vulnerability management ecosystem evolve in most organizations or customers you work with? Are they changing the, the type of the team they're running, or do you see the vulnerability management more towards the right rather than, hey, it's a afterthought after the application's in production, now we're...

Ashish Rajan: 'Cause there's a lot more to what you said about it [00:24:00] almost was creeping into what the SOC does as well. So I'm curious- Yeah ... as to how do you see the dynamics of this, uh, as people progress further into this AI world?

Rich Seiersen: Sure. Sure. That's a great question. So we have a concept of the risk operations center, right?

Rich Seiersen: So if you, if you think of the SOC as a, as a capability, it's not a framework, right? Yeah. It's a, it's a ca- it's an operational capability. Um, s- o- operations is that pivotal word right in the middle of SOC, and same with ROC. And the idea with a ROC is that we're looking to ensure that your, particularly from an exposure management perspective that your capabilities are scaling relative to what you stand to lose, right?

Rich Seiersen: So, and this ch- particularly matters in light of AI. So I, I wanna just step back a little bit 'cause people keep saying, "Well, you know, the world's completely changing 'cause of AI" and whatnot, and I'm-- That, sure, that's fine. But you know what doesn't change? Death and taxes, all right? So when I say death thing th- Instances, phenomenon, events, instances have a time to live.

Rich Seiersen: They ha- they have [00:25:00] mortality. Like this is, if you think about epidemiological stuff, so you-- we use it a lot in actuarial science as well. We're measuring the tendency of how long things to live. So what you have now in light of AI is you have more instances of things that ha- will have, in many cases, a tendency to live longer because of the operational circumstances, meaning because of the software providers, Oracle, Microsoft...

Rich Seiersen: I'm not picking on them, they're just everyone knows them. They're-

Ashish Rajan: Yeah ...

Rich Seiersen: great companies, right? But Oracle, Microsofts of the world and whatnot, that they have a backlog too, right? So if you think of what happened with Glasswing and whatnot, is it took a long time before we started finally seeing patches be- CVEs being announced and patched, 'cause there's just this massive backlog of work.

Rich Seiersen: It's operational work. Y- listen, things come in, like you know, black box in, some state, and then out. And this is the- Yeah ... this is just scientific. This is operations man- operations management, queue management. It's just maths, and that doesn't change. Yeah. And that still doesn't change [00:26:00] here. You, you just, what you have is you just have a macroeconomic rate change.

Rich Seiersen: And so again, what it means for us from a risk operations center perspective is, okay, A, how can we get scale in shrinking really what is the attack surface as it relates to actual exposure that relates or leads to plausible future losses? What-- So what I mean then, again, is that from an intelligence perspective, in terms of how we shrink that attack surface, in terms of hyper prioritization, is we want to look at those things that would get in the way of your enterprise meeting their obligations to their stakeholders.

Rich Seiersen: For example, there was a large manufacturer, not on this continent, that, for example, had a, a major loss to ransomware that impacted- Mm ... both their man- their manufacturing environment, ERP, and other things, right? So they had, they had massive business disruption But the thing is, they're an [00:27:00] ecosystem player, right?

Rich Seiersen: So when I say ecosystem player, there were tens of thousands of providers of, uh, single source providers that were put out of business effectively because of them, right? There's up- that's upstream effects, impacts, and downstream. You might think, well, they're not responsible for those. Those are other companies.

Rich Seiersen: They had to take a, they took a $2.5 billion five-year loan out from their federal government because they didn't have the capital reserves to backstop that. They also didn't have insurance that they failed to bind to insurance. So when we look at the risk operations center in, in, in cases like that, we're trying to say, okay, what-- Your state of exposure, vuln, identity, semantic risk, given your state of exposure, given your capabilities, how good you are at shrinking those instances and shrinking that time to live, what does that mean economically for you?

Rich Seiersen: What does that mean in terms of plausible future loss? And how can you spend your money in such a way where in real time you're reducing loss and getting engineering scale? So that's the [00:28:00] full purpose of the risk operations center. So it's not a, uh, it's not a, um, it's not different in that we're saying you should have a ROC and not have a SOC.

Rich Seiersen: They're both just operational capabilities. SOC is typically very, very much shift right Typically something bad. Yeah. And yeah, it's, but same thing, you want to shrink the mortality of those events that you're dealing with, particularly those ones that where you are actually incurring real loss.

Rich Seiersen: Still the same game applies. The ROC is saying, "Hey, look, our job is to get the environment in such a place where you're reducing the likelihood of those events happening even in the first place by, again, reducing the instances, vuln, identity, semantic, and their time to live. And you're doing it in such a way that your, your focus is really on reducing economic impact to the business and your stakeholders."

Rich Seiersen: So that's the ROC in a nutshell.

Ashish Rajan: So do you... So is it more the prevention story then, the ROC?

Rich Seiersen: It is. It is very much on the prevention side. Yeah. If you wanna be real simple and, and the idea, if, I don't know if you've seen [00:29:00] our images, we have this idea of a martini glass. Martini glass is just a graph where you, you'd look at, hey, you know, we, the, one of the ones we use is, was a Fortune 10 engagement we had where we're, we had N connectors across N vendors coming in, and it, after it landed, after asset normalization and score standardization, it was like 60 million instances.

Rich Seiersen: You pass that through the filter of threat intelligence, meaning active exploitability, meaningful, real exploitability from threat intelligence. You pass it through asset value and, you know, are, is this part of a crown jewel? Is it one or two Kevin Bacon... You know, is the ankle bone connecting to the shin bone connecting to the knee bone where it could lead to loss?

Rich Seiersen: And then you're passing it through actual breach and attack simulation, meaning is it reachable across, you know, same segment, cross segment through inline host-based controls? Can we actually get a, a benign payload there or not? Going through all those filters, what's actually left? Those have to in-- That's happening in real time.

Rich Seiersen: Shrink that down to 24 hours or less. That's gonna have that pr- call that prevention. That's gonna have a natural [00:30:00] impact in helping you scale out whatever happens, whatever eventually might land on the SOC where there's actual, angry packets have success. The, the pirates have successfully stealing treasure 'cause they've fired angry packets across the bow and they're, you know, they're stealing stuff.

Rich Seiersen: That's when the SOC gets engaged. Th-this, the risk operations center is gonna have major financial impact in reducing and giving scale to the SOC. Our belief is that you're gonna be largely using sen- um, some amount of sentient intelligence on the ROC side, heavily artificially intelligent. 'Cause a lot of it's, you're doing a lot of mathematics- Mm.

Rich Seiersen: in terms of correlation- Yeah ... attack paths, sorts of stuff like that, autonomous remediation. So you're really, you're not... The ROC shouldn't, you shouldn't be thinking of, "Hey, I'm gonna build brick and mortar. All of a sudden I'm hiring an army of people." No, you're hiring, hiring ensembles of agents to get this work done.

Rich Seiersen: There'll still be humans involved, obviously, right? But it's more agentic AI being applied in terms of prevention, so shift left for sure.

Ashish Rajan: And do you find that, vulnerability management is across [00:31:00] the board, not just for, uh, on-premise,

Rich Seiersen: you have identity access management, which is a much bigger space. I mean, if you think about- Right ... MITRE ATT&CK, 60% of the techniques involve identity movement, and then you have what we'll call, this comes from MITRE Atlas, semantic risk or AI risk. So I'm looking at those three areas of exposure. And you, so you can talk about... Vuln's important. I started, 'cause Mythos is very vuln focused. But the reality is that, that a, a, a techniques against a vuln is just one state chain. It's not the total attack. It's one part of the attack, and a lot of the movement is actually involved in, really involves some form of escalation of privilege and whatnot.

Rich Seiersen: A lot of the treasure stealing is very much identity-oriented. Now, with AI, of course, you have semantic risk that may not even include any, a, an exploitable state from a vulnerability perspective, meaning from a software or configuration perspective. It may not- Right ... involve any sort of identity control.

Rich Seiersen: This is semantic risk. It's a whole different thing. We deal with that whole stack, so it's really, I really wanna make sure that people are focused on that.

Ashish Rajan: Oh, fair. And I guess to your point, it's a prevention story on exposure management.

Ashish Rajan: In that exposure [00:32:00] management I, I guess, problem that you're tackling, what do you find as a good stepping stone to start showing some, uh, for lack of a better word, runs on the board for people who are trying to start filling that gap up in terms of I've not done AI before, I heard what Rich said.

Ashish Rajan: What's a good place to start? Because exposure management today could be on my data centers, my cloud infrastructure, could be my software, could be Microsoft- Sure ... Oracle, the list goes on. In the customers you've been working with, have you found that, is there a good place to start the exposure management story in- inside- Yes

Ashish Rajan: an organization?

Rich Seiersen: Absolutely. And of course, I'm not gonna go against what I just said. Is it, is it-- I think you should start with, bec- in light of, there was Mythos, we're beyond, we're now in frontier model space. But in light of that, in light of the glut of CVEs, again I just wanted to make sure that people understand exposure management is much bigger than vulns, but vulns are critical.

Rich Seiersen: Yeah. But it's much bigger than that. H- you know, bad guys get that, and the, [00:33:00] uh, white hats get that. But I would start there. I would, I... If I were to work with you, be it you, if you're a customer, if I, you engage with Rich, be it a customer or a prospect, the first thing we're gonna do is benchmark you.

Rich Seiersen: Like that, by the like that. We're gonna benchmark you in terms of your AWE, and we look at the whole tail, right? We look at the whole survival curve. So a lot of the action's in the curve, but we're gonna look at where you are in your AWE and given, and then we're gonna benchmark you against your, against the totality and then against your industry.

Rich Seiersen: And we do another benchmark, then we do an economic benchmark. This is like this, by the way. It's not... This is like we show up to the first meeting with this already done. It's, there, there's no questions. It's done. So then we benchmark you economically as well. So we integrate a bunch of insurance data. We bring in the same data that, that, um, Marsh uses, the same dataset that, AIG, Munich Re, whatnot.

Rich Seiersen: We have that-- We have a massive database of losses m- going over a decade plus. We bring all that in together with the exposure management data. I have a large decision science team, and we go through and we provide two benchmarks, the operational benchmark on where [00:34:00] you are from an AWE perspective against your peers.

Rich Seiersen: And then we are able to say, "Given that, what's the likelihood of you having one or more material loss events per year?" And we benchmark that against your industry peers, typically for companies that are 100 million in revenue or greater, and we can say where you are. So that gives you a pl- so that gives you a place to start and ask the question, okay and th- by the way, the economic one is in light of your revenue, right?

Rich Seiersen: Yeah. And it's in light of y- we are able to ascertain from a data breach regulatory perspective. We're also able to look at uptime, business disruption, and other things. We're able to say, "Okay, given that, you know, how do you compare to your peers?" And then we can start saying, "All right, given what-- where you stand in the industry, given who you are as an ecosystem player," going back to that manufacturing company, "where should you be?"

Rich Seiersen: And people say, "Well, Rich, we don't know where we should be." And I say, "Well, why don't we start with getting you on a plan to get you to a 24-hour AWE?" Why should we do that? Because that is the new floor, as I [00:35:00] mentioned. That's the new floor. You should be at least there "Well, that sounds really drastic."

Rich Seiersen: No, let's talk about how we can get you there in a capitally efficient and operationally efficient manner. Let's do an ROI analysis on that. That's the other part of what we do. So we show up with an ROI analysis. And by the way, I-- listen, I think all vendors should be doing this. They really should be.

Rich Seiersen: It's not it's not... The math is not magic. There's no magic sauce here. And your analysis, by the way, if we sh- when we show up with, "Hey, by the way, here's the exact assumptions we have. Here's-- We've got two years of your data. This is exactly what the reality is. Here's the insurance data.

Rich Seiersen: This is exactly what it says, and we're just gonna show you the, here's the, here's the assumptions, here's the math. Here it is. Ask some questions, throw some tomatoes at it, poke some holes. We're just trying to bring as much analysis as possible to help you make better decisions." There is nothing stopping other vendors from doing that.

Rich Seiersen: In fact, my argument, why I wrote my first book, is I think we should be sciencing the shite out of this, [00:36:00] and we should be using financial, best financial engineering, actuarial science, security operations to bring the best decision-making possible to people who are in asymmetric warfare, particularly right now, so they can make the best capitally and operationally efficient dec- decisions.

Rich Seiersen: By the way, you do that, your CFO will take you out to lunch again. You'll become friends. It'll be amazing. So that's what I do. That's what we do. So the first step, get to a 24-hour AWE. Let's benchmark where you are. Let's look at what the economic impact is of that. Let's look at what the ROI is on those costs, and let's move forward with making decisions.

Rich Seiersen: Again, the reason why you want to use ROI is so that you can compare apples to apples and apples to oranges. You have other things that you need to spend money on. How do you go about making the best decisions given the capital allocations that you have to Make yourself in a much better place on that asymmetric warfare.

Ashish Rajan: That, that's a great answer. And that's all the questions I had as well. So, uh, that, that is towards the end of my interview to you as well. Where can people find you- I was just getting

Rich Seiersen: started. Come on. [00:37:00]

Ashish Rajan: I mean, I wish, I wish I had more time. I was gonna say, where's a good place for people to reach out to you and get to know more about what you guys are bui- building in terms of h- the all the things you've mentioned in terms of highest, the hyper prioritization and the rocks of the world as well.

Ashish Rajan: And I believe- Sure ... you guys have a conference coming up too.

Rich Seiersen: Sure. So two things, obviously qualys.com is great. By the way, if there's something I said that you really, you would like, "Rich, you mentioned this report," and engaging with you, it's, rsirerson@qualys.com, but you can just LinkedIn me and pin- DM me, and I'm very responsive, and we can talk.

Rich Seiersen: And yeah, we do these reports for, uh, prospects, that means you're not a customer, and we do them for customers as well. If you want to-- And we do them- Nice ... you'd have to get a briefing with me 'cause we don't want people running around on, on the highway with scissors. We want you to make sure you understand the analytics.

Rich Seiersen: So there's that. More importantly, for, particularly for customers and prospects, we have rocon on, risk, the risk operation center or Rock on, R-O-C-O-N. Rock on, our big conference is coming in October in Austin. So if you like blues and rock and roll and, [00:38:00] um, barbecue, and you wanna come out, come hang out and see what we're doing, the bleeding edge work on the risk operations center and exposure management, that includes identity, semantic risk and vuln, and how we're bringing that all together, MCP and all that stuff, come on out.

Rich Seiersen: Come to ROCON. You can go to our, again, go to qualys.com, and you can see where the, where that event is. You can register. But again, feel free to reach out to me directly as well.

Ashish Rajan: Just the combination of security, uh, music, and barbecue should be enough for a lot of people to consider it as well.

Ashish Rajan: I'll put the links for- Yeah ... all of that in the show notes as well, including a link for your LinkedIn too. But thank you so much for coming on the show. I really appreciate the conversation. I look forward to another part two for this, hopefully soon as well.

Rich Seiersen: Great, Ashish. Thank you so much. It really, really a lot of fun.

Rich Seiersen: Thank you so much.

Ashish Rajan: Thanks, everyone. Thanks for tuning in. Thank you for listening or watching this episode of "Cloud Security Podcast." This was brought to you by techriot.io. If you are enjoying episodes on cloud security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple, [00:39:00] Spotify.

Ashish Rajan: In case you are interested in learning about AI security as well, do check out our sister podcast called "AI Security Podcast," which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security. Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at "Cloud Security Podcast."

Ashish Rajan: You can check that out on cloudsecuritynewsletter.com. I'll see you in the next episode.

Peace.

‍

No items found.
More Videos